← 返回 Skills 市场
293
总下载
0
收藏
0
当前安装
3
版本数
在 OpenClaw 中安装
/install pg-buy
功能描述
Use when buying API access through ProxyGate — depositing USDC, browsing available APIs, making proxy requests, streaming responses, or rating sellers. Make...
安全使用建议
This skill seems to be a legitimate ProxyGate buyer helper, but it tells the agent to use your local Solana keypair and CLI to deposit/withdraw USDC and to proxy arbitrary API requests — actions that require access to sensitive secrets and can move money. Before installing: (1) verify the skill's provenance (homepage, author, and source code) — this skill has no homepage listed; (2) assume the agent will need access to ~/.proxygate/keypair.json and ~/.proxygate/config.json or an API key; do not expose your full wallet/private key unless you trust the skill and its author; (3) prefer using a dedicated limited-funds wallet or test keypair and enable dry-run flags when possible; (4) require explicit user confirmation for any deposit/withdraw commands (ask the platform maintainer how to enforce confirmation); (5) if you cannot verify the author or you need stricter guarantees, decline or restrict the skill until it declares required credentials and a clear consent flow.
功能分析
Type: OpenClaw Skill
Name: pg-buy
Version: 0.2.1
The skill bundle facilitates interaction with 'ProxyGate,' a service for purchasing API access using USDC on the Solana blockchain. It includes high-risk capabilities such as managing private Solana keypairs (~/.proxygate/keypair.json), executing financial transactions (deposits and withdrawals), and routing potentially sensitive API traffic through a third-party gateway (https://gateway.proxygate.ai). While these actions are aligned with the stated purpose in SKILL.md and references/commands.md, the automated handling of crypto wallets and the proxying of data constitute significant security risks.
能力评估
Purpose & Capability
The skill's stated purpose (buying API access through ProxyGate) matches the CLI/SDK commands in SKILL.md: balance checks, deposits, proxy requests, ratings, withdrawals. Requiring a Solana wallet or API key is logically consistent with that purpose. However, the skill metadata declares no required env vars or config paths, while the instructions explicitly reference a keypair path (~/.proxygate/keypair.json) and config (~/.proxygate/config.json). That mismatch is unexpected and should have been declared.
Instruction Scope
The SKILL.md tells the agent to run commands that access local wallet/keypair files, initialize a vault, deposit USDC (on-chain), withdraw funds, and proxy arbitrary upstream API requests (including streaming and shield modes). These actions involve sensitive local files and financial transactions and will send data to external endpoints (gateway.proxygate.ai and upstream APIs). The instructions also encourage always using this skill for many user intents, giving broad discretion. There is no explicit requirement in the document that the agent must obtain explicit user confirmation before performing fund-moving commands.
Install Mechanism
This is an instruction-only skill with no install spec and no code files. That reduces attack surface from supply-chain installs; the skill will only instruct the agent to call existing CLI/SDK tools assumed to be present.
Credentials
The skill metadata lists no required environment variables or credentials, yet the docs reference API keys and a Solana keypair file, and CLI flags exist to override API key or point to a keypair. Those are sensitive secrets (wallet private keys / API keys) and should have been declared. The agent may be directed to read or use these secrets, which is disproportionate relative to the declared (empty) requirements.
Persistence & Privilege
always: false (good), but the skill is allowed autonomous invocation (platform default). Combined with the ability to perform deposits/withdrawals and the SKILL.md's recommendation to 'Make sure to use this skill whenever...' this gives an autonomously-invoked skill the potential to perform financial operations without clear manual confirmation. That combination increases risk and should be mitigated by requiring explicit user consent for fund-moving actions.
如何使用
- 确保已安装 OpenClaw(本地或 Docker 部署)
- 在对话框中输入安装命令:
/install pg-buy - 安装完成后,直接呼叫该 Skill 的名称或使用
/pg-buy触发 - 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v0.2.1
Sync with CLI v0.2.1 — updated commands, descriptions, and examples
v1.0.1
Add openclaw metadata: declare required binary (proxygate)
v1.0.0
Initial release of ProxyGate API-buying skill.
- Enables buying API access through ProxyGate: deposit USDC, discover APIs, make proxy requests, stream responses, and rate sellers.
- CLI commands and SDK usage included for full buyer workflow.
- Filtering, browsing, and searching APIs by category, service, and features.
- Added shield scanning for proxy requests (content moderation).
- Includes instructions for checking usage, settlements, and withdrawing USDC.
- Explicit skill invocation guidance for relevant user intents (API buying, proxy requests, deposits, etc.).
元数据
常见问题
Pg Buy 是什么?
Use when buying API access through ProxyGate — depositing USDC, browsing available APIs, making proxy requests, streaming responses, or rating sellers. Make... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 293 次。
如何安装 Pg Buy?
在 OpenClaw 或 Claude Code 对话框中运行命令「/install pg-buy」即可一键安装,无需额外配置。
Pg Buy 是免费的吗?
是的,Pg Buy 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。
Pg Buy 支持哪些平台?
Pg Buy 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。
谁开发了 Pg Buy?
由 jwelten(@jwelten)开发并维护,当前版本 v0.2.1。
推荐 Skills